vm-clone

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The vm-clone skill presents a coherent, security-conscious design for cloning OpenShift Virtualization VMs. It appropriately relies on cluster-native MCP tools and RBAC controls, mandates user confirmation to prevent unintended resource usage, and keeps credentials (like KUBECONFIG) protected. The data flows are contained within the cluster, and no external data exfiltration or dangerous supply-chain patterns are observed. Overall, the skill is BENIGN with LOW to MEDIUM risk primarily related to cluster resource consumption and RBAC permission scope, which are inherent to its purpose.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 04:05 PM
Package URL
pkg:socket/skills-sh/RHEcosystemAppEng%2Fagentic-collections%2Fvm-clone%2F@c7e0e6bd331a75da29592237413e7787f75bc18a